Skip to content
OPS // KITitspentest.sh

X-O36

o365spray

Username enumeration and password-spraying tool targeting Microsoft O365/Entra ID authentication endpoints, with built-in lockout throttling.

Official siteBack to catalog

OVERVIEW

o365spray (0xZDH/o365spray) is a Python tool purpose-built against Microsoft O365/Entra ID authentication surfaces. Its `--validate` module confirms a domain is backed by O365, `--enum` checks whether individual usernames exist using techniques like Autologon, OAuth2, and RST endpoint responses, and `--spray` runs a password spray against a supplied username list.

What sets it apart from generic spray tools is that it is explicitly documented, in its own README, as account-lockout aware: the enumeration modules that make one authentication attempt per user will automatically reset the tenant's lockout timer before a subsequent spray runs in the same execution, and the tool exposes `--count` and `--lockout` flags so an operator can pace attempts to a client's actual lockout policy.

USE CASES

Practical use cases

  • 01

    Validating that a target domain is backed by Microsoft O365/Entra ID before investing further recon effort.

  • 02

    Enumerating which addresses in a harvested list correspond to real, valid tenant accounts.

  • 03

    Running rate-limited password spraying against a vetted, client-approved password list.

  • 04

    Routing enumeration and spray traffic through FireProx-style rotating endpoints to test detection coverage rather than raw success rate.

QUICK START

Once password-spraying against a client's O365/Entra ID tenant is explicitly authorized, to validate the tenant, enumerate valid usernames, and spray a vetted password list against real accounts.

  1. Confirm the specific domain, username list, and password list are all within the signed authorization before running anything against it.
  2. Validate the tenant: `o365spray --validate --domain target.com`.
  3. Enumerate valid usernames against the harvested list: `o365spray --enum -U usernames.txt --domain target.com`.
  4. Spray only with the client-approved passwords, respecting the tenant's real lockout threshold: `o365spray --spray -U usernames.txt -P passwords.txt --count 1 --lockout 10 --domain target.com`.
o365spray — bash
o365spray --enum -U usernames.txt --domain target.com

BEFORE YOU RUN IT

What to check before running it

Password spraying targets real end-user accounts, not just infrastructure — it must be explicitly authorized in writing, with the client's actual lockout policy and password list agreed in advance, separately from any infrastructure-only recon authorization.

Getting `--count`/`--lockout` wrong locks out real users and generates helpdesk tickets; always pace spraying below the tenant's documented lockout threshold and coordinate timing with the client's SOC.

Enumeration and spray attempts appear as authentication events in Entra ID sign-in logs (often as many failed sign-ins from a single source); agree with the client on what to expect there for the blue-team debrief.

KEEP EXPLORING

View the whole phase →